WEPLUGINS WP Maps Lite Edition for WordPress

CPE Details

WEPLUGINS WP Maps Lite Edition for WordPress
-
2025-05-07
11h35 +00:00
2025-05-07
11h35 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:weplugins:wp_maps:-:*:*:*:lite:wordpress:*:*

Informations

Vendor

weplugins

Product

wp_maps

Version

-

Software Edition

lite

Target Software

wordpress

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2025-3504 2025-05-01 06h00 +00:00 The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
4.8
Medium
CVE-2025-3503 2025-05-01 06h00 +00:00 The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
4.8
Medium
CVE-2025-3502 2025-05-01 06h00 +00:00 The WP Maps WordPress plugin before 4.7.2 does not sanitise and escape some of its Map settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
4.8
Medium
CVE-2023-28172 2023-11-12 22h24 +00:00 Cross-Site Request Forgery (CSRF) vulnerability in flippercode WordPress Plugin for Google Maps – WP MAPS (formerly WP Google Map Plugin) plugin <= 4.4.2 versions.
8.8
High
CVE-2023-23878 2023-04-04 11h38 +00:00 Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in flippercode WordPress Plugin for Google Maps – WP MAPS plugin <= 4.3.9 versions.
5.9
Medium
CVE-2022-25600 2022-03-11 17h54 +00:00 Cross-Site Request Forgery (CSRF) vulnerability affecting Delete Marker Category, Delete Map, and Copy Map functions in WP Google Map plugin (versions <= 4.2.3).
8.8
High
CVE-2021-24502 2021-08-09 08h04 +00:00 The WP Google Map WordPress plugin before 1.7.7 did not sanitise or escape the Map Title before outputting them in the page, leading to a Stored Cross-Site Scripting issue by high privilege users, even when the unfiltered_html capability is disallowed
4.8
Medium
CVE-2021-24130 2021-03-18 13h57 +00:00 Unvalidated input in the WP Google Map Plugin WordPress plugin, versions before 4.1.5, in the Manage Locations page within the plugin settings was vulnerable to SQL Injection through a high privileged user (admin+).
7.2
High
CVE-2015-9307 2019-08-14 13h24 +00:00 The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit location feature.
8.8
High
CVE-2015-9308 2019-08-14 13h23 +00:00 The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit map feature.
8.8
High
CVE-2015-9309 2019-08-14 13h22 +00:00 The wp-google-map-plugin plugin before 2.3.10 for WordPress has CSRF in the add/edit category feature.
8.8
High
CVE-2016-10878 2019-08-12 12h52 +00:00 The wp-google-map-plugin plugin before 3.1.2 for WordPress has XSS.
6.1
Medium
CVE-2015-9305 2019-08-12 12h51 +00:00 The wp-google-map-plugin plugin before 2.3.7 for WordPress has XSS related to the add_query_arg() and remove_query_arg() functions.
6.1
Medium